Skip to main content

Platform compatibility

macOSWindowsLinuxiOS / iPadOSAndroid

How to set it up

1

Choose your enforcement mode

  • Blocklist: all applications are allowed except those explicitly listed.
  • Allowlist: only the applications you list are permitted to run.
2

Add applications

Add applications by their bundle identifier (e.g. com.spotify.client) or executable name.
To find an application’s bundle identifier on macOS, run the following command in Terminal:osascript -e 'id of app "AppName"'
3

Save and apply

Save and apply the control to the relevant device group.

Modifying or removing the control

Disable the control from the profile settings. Disabling stops enforcement but does not remove existing configurations from devices.

How it works

Once deployed, macOS evaluates running applications against the policy. Blocked applications are terminated and users see a system notification explaining that the application is not permitted. The policy is enforced continuously — if a user installs a blocked application after the control is applied, it will be prevented from running the next time they attempt to open it.

Troubleshooting

An allowed application is being blocked
  • Double-check the bundle identifier for typos — identifiers are case-sensitive.
  • Confirm the control is targeting the correct device group.
  • Re-check the enforcement mode: if using an allowlist, make sure the application is explicitly listed.
A blocked application is still running
  • The policy is applied at launch time. If the application was already open when the policy was deployed, restart the device or ask the user to quit and reopen the application.